Prompt Injection
The latest Prompt Injection coverage — news, analysis, and updates from the WindowsNews.AI desk.
Copilot Agent Blocking Broken: Admins Discover Policies Fail Across Teams, Outlook
Organizations relying on Microsoft Copilot's agent policies to restrict AI access are confronting a stark reality: the controls have been breaking silently. In recent weeks, multiple independent...
Visual Studio MCP GA Brings GitHub Server v0.12.1, but Prompt Injection Risks Demand Vigilance
Microsoft has shipped general availability support for the Model Context Protocol (MCP) directly into Visual Studio, letting developers connect Copilot Chat to external services through a simple...
Microsoft Quietly Patches Copilot Flaw That Let Insiders Access Files Without Audit Traces
A security researcher discovered that a simple prompt technique could make Microsoft 365 Copilot summarize sensitive corporate files without leaving the required Purview audit records. Microsoft...
Tenable AI Exposure Debuts at Black Hat to Tackle Generative AI’s Hidden Attack Surface
Tenable today took the wraps off Tenable AI Exposure, a new module within its Tenable One exposure management platform designed to help enterprises discover, prioritize, and govern risks introduced...
ChatGPT Gets Gmail and Calendar Access: OpenAI's Productivity Play Raises Security Flags
OpenAI has quietly breached the walls of Google Workspace. Starting this week, ChatGPT Pro users can grant the AI direct access to their Gmail inboxes, Google Calendars, and Google Contacts—turning...
Zenity Labs Unveils AgentFlayer: Zero-Click Exploits Hijack ChatGPT, Microsoft Copilot, and Salesforce Einstein
Zenity Labs has dropped a bombshell at Black Hat USA 2025: a new attack framework called AgentFlayer that lets adversaries silently hijack enterprise AI agents without so much as a mouse click....
Microsoft’s AI Coding Assistant Under Fire as GitHub Copilot Command Injection Chain Exposes Developers to Remote Code Execution
A zero-click AI command injection flaw in Microsoft 365 Copilot, tracked as CVE-2025-32711 and nicknamed EchoLeak, laid bare a dangerous new attack surface in June 2025. The vulnerability carried a...
AgentFlayer Unleashed: Zero-Click Chains Turn Enterprise AI Agents into Stealth Insider Threats
At Black Hat USA 2025, Zenity Labs peeled back the curtain on a threat that security teams have long feared but rarely seen weaponized at scale: zero-click prompt injection attacks that silently...
GPT-5 Launch Sparks Musk-Nadella Clash, But Azure’s Model Router Quietly Redefines the Enterprise AI Battle
Elon Musk’s blunt warning that “OpenAI is going to eat Microsoft alive” after the August 7, 2025 launch of GPT‑5 crystallized a volatile moment in enterprise AI, but the far more telling...
Poisoned Calendars, Hijacked Chips, and Stealthy Phishing: Inside the Latest Cybersecurity Onslaught
A single poisoned Google Calendar invite can now raise your smart blinds and start a Zoom call without your consent. That unsettling reality emerged at this year’s Black Hat conference, where...
Google Gemini Exploit Can Control Smart Homes, as Nvidia Rejects Government Backdoor Demands
A simple "thank you" is all it takes for attackers to hijack Google's Gemini AI and control your smart home, researchers revealed at Black Hat this week. The demonstration, which showed how a...
Black Hat 2025: Zero-Click Exploits Can Hijack ChatGPT, Copilot, and Einstein Without a Trace
Security researchers at Zenity Labs have dropped a bombshell at Black Hat USA 2025: a new breed of zero-click exploit chains can silently hijack enterprise AI agents, including OpenAI’s ChatGPT,...